)]}'
{"id":"openvpn~449","triplet_id":"openvpn~master~I0ad48915004ddee587e97c8ed190ba8ee989e48d","project":"openvpn","branch":"master","full_branch":"refs/heads/master","topic":"tlsalerts","attention_set":{},"removed_from_attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2024-06-01 20:27:37.000000000","reason":"Change was submitted"},"1000001":{"account":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"last_update":"2023-11-28 13:35:35.000000000","reason":"\u003cGERRIT_ACCOUNT_1000001\u003e replied on the change","reason_account":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."}}},"hashtags":["mailsubmitted"],"change_id":"I0ad48915004ddee587e97c8ed190ba8ee989e48d","subject":"Allow the TLS session to send out TLS alerts","status":"MERGED","created":"2023-11-20 11:27:58.000000000","updated":"2024-06-01 20:27:37.000000000","submitted":"2024-06-01 20:27:37.000000000","submitter":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"total_comment_count":21,"unresolved_comment_count":1,"has_review_started":true,"submission_id":"449-tlsalerts","meta_rev_id":"67364f1d787f9b9f34fa2925d748076545c6220d","_number":449,"virtual_id_number":449,"owner":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},{"value":0,"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2023-11-20 11:27:58.000000000","updated_by":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"real_updated_by":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2023-11-20 11:27:58.000000000","updated_by":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"real_updated_by":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"reviewer":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"state":"REVIEWER"}],"messages":[{"id":"7f356f84e02ae0ea6ff1b6d42128a39238173b5b","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-11-20 11:27:58.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"8f5e47aa3d3ce87a5567f7f965ad46ea16601d05","author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2023-11-20 11:55:56.000000000","message":"Patch Set 1: Code-Review-2\n\n(9 comments)","accounts_in_message":[],"_revision_number":1},{"id":"cfcb63acedfe6625ab9db44bf4cb3ba6c38e4360","author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-11-20 13:02:18.000000000","message":"Patch Set 1:\n\n(8 comments)","accounts_in_message":[],"_revision_number":1},{"id":"2646c187ad8ad3cb52c1fef979b3d588a4623664","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-11-20 13:02:31.000000000","message":"Uploaded patch set 2.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":2},{"id":"e9fd2c0bc161a809cd40b1a0fa3662b4cabdc169","author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2023-11-20 13:08:11.000000000","message":"Patch Set 2: Code-Review+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"65bf167ee45c7be547a243581d25ef81884c9a91","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-11-20 13:26:26.000000000","message":"Uploaded patch set 3.\n\nOutdated Votes:\n* Code-Review+1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":3},{"id":"87e9da1f2fcd88ad6d181200d62fa56077dac31e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-11-20 14:35:32.000000000","message":"Uploaded patch set 4.","accounts_in_message":[],"_revision_number":4},{"id":"83dc89926b2ed38485070f38ea6db9bac32b8e76","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-11-20 17:10:59.000000000","message":"Uploaded patch set 5.","accounts_in_message":[],"_revision_number":5},{"id":"36be05aaa82845f93b7fe4a4ea64b23160cd5d43","author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2023-11-28 13:35:35.000000000","message":"Patch Set 5:\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"8471dcd9676ba538b692d14e3d1d4186789cf4b4","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2024-01-02 13:56:24.000000000","message":"Uploaded patch set 6.","accounts_in_message":[],"_revision_number":6},{"id":"1b288677817dd4b2204e977f61ffc13373b7e9f2","author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2024-03-18 16:30:01.000000000","message":"Patch Set 6: Code-Review+2\n\n(2 comments)","accounts_in_message":[],"_revision_number":6},{"id":"429ba61b3b8ddacdcb4b096610f5053851445ea5","tag":"autogenerated:gerrit:setHashtag","author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2024-04-08 12:49:46.000000000","message":"Hashtag added: mailsubmitted","accounts_in_message":[],"_revision_number":6},{"id":"67364f1d787f9b9f34fa2925d748076545c6220d","tag":"autogenerated:gerrit:merged","author":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2024-06-01 20:27:37.000000000","message":"Change has been successfully pushed.","accounts_in_message":[],"_revision_number":7}],"current_revision_number":7,"current_revision":"fbe3b49b373ea8e81aaa31a383258403a3bfcd07","revisions":{"1c17880327486961b54c13500cd5e2c0778ad427":{"kind":"REWORK","_number":1,"created":"2023-11-20 11:27:58.000000000","uploader":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/49/449/1","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/49/449/1","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/1 \u0026\u0026 git checkout -b change-449 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/49/449/1","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"b2718758d7aeafc4d77afd5e42124b50ff1aaf1b","subject":"Log SSL alerts more prominently"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-10-24 12:08:30.000000000","tz":120},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-11-20 11:27:45.000000000","tz":120},"subject":"Allow the TLS session to send out TLS alerts","message":"Allow the TLS session to send out TLS alerts\n\nPrevious OpenVPN versions shut down the TLS control channel immediately\nwhen encountering an error. This also meant that we would not send out\nTLS alerts to notify a client about potential problems like mismatching\nTLS versions or having no common cipher.\n\nThis commit adds a new key_state S_ERROR_PRE which still allows to\nsend out the remaining TLS packets of the control session which are\ntypically the alert message and then going to S_ERROR. We do not\nwait for retries. So this is more a one-shot notify but that is\nacceptable in this situation.\n\nSending out alerts  is a slight compromise in security as alerts give\nout a bit of information that otherwise is not given\nout. But since all other consumers TLS implementation are already doing this\nand TLS implementation (nowadays) are very careful not to leak (sensitive)\ninformation by alerts and since the user experience is much better with\nalerts, this compromise is worth it.\n\nChange-Id: I0ad48915004ddee587e97c8ed190ba8ee989e48d\n"},"branch":"refs/heads/master"},"ed72e2c8fc699aa0833ac5394a1b322de794afc3":{"kind":"REWORK","_number":2,"created":"2023-11-20 13:02:31.000000000","uploader":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/49/449/2","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/49/449/2","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/2 \u0026\u0026 git checkout -b change-449 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/49/449/2","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"0867c42f4975e317e7f33e7931c3a0ae0da1e675","subject":"Rename state_change to continue_tls_process"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-10-24 12:08:30.000000000","tz":120},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-11-20 13:00:18.000000000","tz":120},"subject":"Allow the TLS session to send out TLS alerts","message":"Allow the TLS session to send out TLS alerts\n\nPrevious OpenVPN versions shut down the TLS control channel immediately\nwhen encountering an error. This also meant that we would not send out\nTLS alerts to notify a client about potential problems like mismatching\nTLS versions or having no common cipher.\n\nThis commit adds a new key_state S_ERROR_PRE which still allows to\nsend out the remaining TLS packets of the control session which are\ntypically the alert message and then going to S_ERROR. We do not\nwait for retries. So this is more a one-shot notify but that is\nacceptable in this situation.\n\nSending out alerts is a slight compromise in security as alerts give\nout a bit of information that otherwise is not given\nout. But since all other consumers TLS implementations are already doing this\nand TLS implementations (nowadays) are very careful not to leak (sensitive)\ninformation by alerts and since the user experience is much better with\nalerts, this compromise is worth it.\n\nChange-Id: I0ad48915004ddee587e97c8ed190ba8ee989e48d\n"},"branch":"refs/heads/master"},"b03b733f1661c3a6c7ced2b425ded4152fb790f5":{"kind":"REWORK","_number":3,"created":"2023-11-20 13:26:26.000000000","uploader":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/49/449/3","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/49/449/3","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/3 \u0026\u0026 git checkout -b change-449 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/49/449/3","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"f5aac3fb0a0d726e021f9ab76c86e49ca057381e","subject":"Rename state_change to continue_tls_process"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-10-24 12:08:30.000000000","tz":120},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-11-20 13:26:07.000000000","tz":120},"subject":"Allow the TLS session to send out TLS alerts","message":"Allow the TLS session to send out TLS alerts\n\nPrevious OpenVPN versions shut down the TLS control channel immediately\nwhen encountering an error. This also meant that we would not send out\nTLS alerts to notify a client about potential problems like mismatching\nTLS versions or having no common cipher.\n\nThis commit adds a new key_state S_ERROR_PRE which still allows to\nsend out the remaining TLS packets of the control session which are\ntypically the alert message and then going to S_ERROR. We do not\nwait for retries. So this is more a one-shot notify but that is\nacceptable in this situation.\n\nSending out alerts is a slight compromise in security as alerts give\nout a bit of information that otherwise is not given\nout. But since all other consumers TLS implementations are already doing this\nand TLS implementations (nowadays) are very careful not to leak (sensitive)\ninformation by alerts and since the user experience is much better with\nalerts, this compromise is worth it.\n\nChange-Id: I0ad48915004ddee587e97c8ed190ba8ee989e48d\n"},"branch":"refs/heads/master"},"6d08aa74470f4aa25d9d799f306c2ed18ecc259c":{"kind":"REWORK","_number":4,"created":"2023-11-20 14:35:32.000000000","uploader":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/49/449/4","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/49/449/4","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/4 \u0026\u0026 git checkout -b change-449 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/49/449/4","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"f5aac3fb0a0d726e021f9ab76c86e49ca057381e","subject":"Rename state_change to continue_tls_process"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-10-24 12:08:30.000000000","tz":120},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-11-20 14:35:20.000000000","tz":60},"subject":"Allow the TLS session to send out TLS alerts","message":"Allow the TLS session to send out TLS alerts\n\nPrevious OpenVPN versions shut down the TLS control channel immediately\nwhen encountering an error. This also meant that we would not send out\nTLS alerts to notify a client about potential problems like mismatching\nTLS versions or having no common cipher.\n\nThis commit adds a new key_state S_ERROR_PRE which still allows to\nsend out the remaining TLS packets of the control session which are\ntypically the alert message and then going to S_ERROR. We do not\nwait for retries. So this is more a one-shot notify but that is\nacceptable in this situation.\n\nSending out alerts is a slight compromise in security as alerts give\nout a bit of information that otherwise is not given\nout. But since all other consumers TLS implementations are already doing this\nand TLS implementations (nowadays) are very careful not to leak (sensitive)\ninformation by alerts and since the user experience is much better with\nalerts, this compromise is worth it.\n\nChange-Id: I0ad48915004ddee587e97c8ed190ba8ee989e48d\n"},"branch":"refs/heads/master"},"5bccaaca12c6d1786b5e1a73e58eb7820c1d7814":{"kind":"REWORK","_number":5,"created":"2023-11-20 17:10:59.000000000","uploader":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/49/449/5","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/49/449/5","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/5 \u0026\u0026 git checkout -b change-449 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/49/449/5","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/5 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"0c0d7cd4ba49fe2f2d15cc55a07a5832d36a9889","subject":"Rename state_change to continue_tls_process"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-10-24 12:08:30.000000000","tz":120},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-11-20 17:10:24.000000000","tz":60},"subject":"Allow the TLS session to send out TLS alerts","message":"Allow the TLS session to send out TLS alerts\n\nPrevious OpenVPN versions shut down the TLS control channel immediately\nwhen encountering an error. This also meant that we would not send out\nTLS alerts to notify a client about potential problems like mismatching\nTLS versions or having no common cipher.\n\nThis commit adds a new key_state S_ERROR_PRE which still allows to\nsend out the remaining TLS packets of the control session which are\ntypically the alert message and then going to S_ERROR. We do not\nwait for retries. So this is more a one-shot notify but that is\nacceptable in this situation.\n\nSending out alerts is a slight compromise in security as alerts give\nout a bit of information that otherwise is not given\nout. But since all other consumers TLS implementations are already doing this\nand TLS implementations (nowadays) are very careful not to leak (sensitive)\ninformation by alerts and since the user experience is much better with\nalerts, this compromise is worth it.\n\nChange-Id: I0ad48915004ddee587e97c8ed190ba8ee989e48d\n"},"branch":"refs/heads/master"},"e2a9651d8beb73f99905d422176b5fc66458803f":{"kind":"REWORK","_number":6,"created":"2024-01-02 13:56:24.000000000","uploader":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/49/449/6","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/49/449/6","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/6 \u0026\u0026 git checkout -b change-449 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/49/449/6","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/6 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"76d11614797617708c31dc3db22e3568fee3de6d","subject":"get_default_gateway() HWADDR overhaul"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-10-24 12:08:30.000000000","tz":120},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2024-01-02 13:55:58.000000000","tz":60},"subject":"Allow the TLS session to send out TLS alerts","message":"Allow the TLS session to send out TLS alerts\n\nPrevious OpenVPN versions shut down the TLS control channel immediately\nwhen encountering an error. This also meant that we would not send out\nTLS alerts to notify a client about potential problems like mismatching\nTLS versions or having no common cipher.\n\nThis commit adds a new key_state S_ERROR_PRE which still allows to\nsend out the remaining TLS packets of the control session which are\ntypically the alert message and then going to S_ERROR. We do not\nwait for retries. So this is more a one-shot notify but that is\nacceptable in this situation.\n\nSending out alerts is a slight compromise in security as alerts give\nout a bit of information that otherwise is not given\nout. But since all other consumers TLS implementations are already doing this\nand TLS implementations (nowadays) are very careful not to leak (sensitive)\ninformation by alerts and since the user experience is much better with\nalerts, this compromise is worth it.\n\nChange-Id: I0ad48915004ddee587e97c8ed190ba8ee989e48d\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"fbe3b49b373ea8e81aaa31a383258403a3bfcd07":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":7,"created":"2024-06-01 20:27:37.000000000","uploader":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/49/449/7","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/49/449/7","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/7 \u0026\u0026 git checkout -b change-449 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/49/449/7","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/449/7 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"55bb3260c12bae33b6a8eac73cbb6972f8517411","subject":"Only schedule_exit() once"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2024-04-08 12:49:33.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2024-06-01 13:07:05.000000000","tz":120},"subject":"Allow the TLS session to send out TLS alerts","message":"Allow the TLS session to send out TLS alerts\n\nPrevious OpenVPN versions shut down the TLS control channel immediately\nwhen encountering an error. This also meant that we would not send out\nTLS alerts to notify a client about potential problems like mismatching\nTLS versions or having no common cipher.\n\nThis commit adds a new key_state S_ERROR_PRE which still allows to\nsend out the remaining TLS packets of the control session which are\ntypically the alert message and then going to S_ERROR. We do not\nwait for retries. So this is more a one-shot notify but that is\nacceptable in this situation.\n\nSending out alerts is a slight compromise in security as alerts give\nout a bit of information that otherwise is not given\nout. But since all other consumers TLS implementations are already doing this\nand TLS implementations (nowadays) are very careful not to leak (sensitive)\ninformation by alerts and since the user experience is much better with\nalerts, this compromise is worth it.\n\nChange-Id: I0ad48915004ddee587e97c8ed190ba8ee989e48d\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\nAcked-by: Frank Lichtenheld \u003cfrank@lichtenheld.com\u003e\nMessage-Id: \u003c20240408124933.243991-1-frank@lichtenheld.com\u003e\nURL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg28540.html\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[]}
